Debian DLA-3281-1 : swift – LTS security update

The remote Debian 10 host has packages installed that are affected by a vulnerability as referenced in the dla-3281 advisory. - An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x befor ...

Continue Reading

CVSS3 - MEDIUM

Amazon Linux 2022 : (ALAS2022-2022-210)

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2022-2022-210 advisory. - containerd is a container runtime available as a daemon for Linux and Windows. A bug was fou ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

Security Updates for Azure CycleCloud (Nov 2022)

The Azure CycleCloud product is missing security updates. It is, therefore, affected by an elevation of privilege vulnerability. An unauthenticated, adjacent attacker can exploit this, via brute force ...

Continue Reading

CVSS3 - HIGH

JWT audience claim is not verified

### Impact All versions of Argo CD starting with v1.8.2 are vulnerable to an improper authorization bug causing the API to accept certain invalid tokens. OIDC providers include an `aud` (audience) cla ...

Continue Reading
JWT audience claim is not verified

### Impact All versions of Argo CD starting with v1.8.2 are vulnerable to an improper authorization bug causing the API to accept certain invalid tokens. OIDC providers include an `aud` (audience) cla ...

Continue Reading
Amazon Linux 2022 : (ALAS2022-2023-274)

It is, therefore, affected by multiple vulnerabilities as referenced in the ALAS2022-2023-274 advisory. - Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalati ...

Continue Reading

CVSS3 - HIGH

FreeBSD : chromium — multiple vulnerabilities (3d0a3eb0-9ca3-11ed-a925-3065ec8fd3ec)

The version of FreeBSD installed on the remote host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the 3d0a3eb0-9ca3-11ed-a925-3065ec8fd3ec advisor ...

Continue Reading
CVE-2023-22482

A flaw was found in ArgoCD. GitOps is vulnerable to an improper authorization bug where the API may accept invalid tokens. ID providers include an audience claim in signed tokens, which may be used to ...

Continue Reading

Back to Main

Subscribe for the latest news: